11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-25015
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24470
Yada Wiki Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue

CVE-2021-34546
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.

CVE-2021-25027
PowerPack Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2014-7238
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS

CVE-2015-9272
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.8%
2015 1 PoC

The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.

CVE-2021-24556
Email Subscriber Web Windows
N/A
UNKNOWN
EPSS
1.3%
2021 CWE-79 2 PoCs

The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, inserting them in the DB and then outputting them back in the Subscriber list (/wp-admin/edit.php?post_type=kes_campaign&page=kento_email_subscriber_list_settings), leading a Stored XSS issue.

CVE-2021-24807
Support Board Web Windows
N/A
UNKNOWN
EPSS
7.0%
2021 CWE-79 4 PoCs

The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed.

CVE-2021-24356
Simple 301 Redirects by BetterLinks Web Windows
N/A
UNKNOWN
EPSS
44.3%
2021 CWE-862 2 PoCs

In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites.

CVE-2021-24639
OMGF | Host Google Fonts Locally Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-862 1 PoC

The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

CVE-2021-24898
Editable Table Simple Fast FrontEnd From Sql tables Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2015-5559
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.8%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5127, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5550, CVE-2015-5551, CVE-2015-5556, CVE-2015-5557, CVE-2015-5561, CVE-2015-5563, CVE-2015-5564, and CVE-2015-5565.

CVE-2021-24402
WP iCommerce – the first interactive ecommerce for wordpress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

CVE-2021-25097
LabTools Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication

CVE-2021-24851
Insert Pages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.

CVE-2021-25010
Post Snippets Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting issues

CVE-2021-24162
Responsive Menu – Create Mobile-Friendly Menu Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

CVE-2021-24324
404 SEO Redirection Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues

CVE-2007-4000
Software Genérico Windows
N/A
UNKNOWN
EPSS
24.5%
2007 3 PoCs

The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.

CVE-2014-4557
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for-jigoshop) plugin 3.1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.